The file_storage.index() view function didn't sanitize its input. This made is possible for an attacker to overwrite any file, including the files of Pillar itself.
Pillar
This is the latest iteration on the Attract project. We are building a unified framework called Pillar. Pillar will combine Blender Cloud and Attract. You can see Pillar in action on the Blender Cloud.
Description
Languages
Python
65.7%
JavaScript
12.5%
Sass
11.8%
Pug
7.9%
CSS
1.7%
Other
0.4%